Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium
A security team is performing a vulnerability assessment on a critical internal server. They have administrator credentials for the server and intend to use them during the scan to get a comprehensive view of potential vulnerabilities, including misconfigurations and missing patches. What type of scan is being performed?
- AExternal scan
- BGray-box scan
- CBlack-box scan
- DWhite-box scan
Show answer & explanationAnswer & explanation
Correct answer: D. White-box scan
A white-box scan (or credentialed scan) involves providing the scanner with authentication credentials (like administrator access) to allow it to delve deeper into the system, inspect configurations, and check for missing patches more thoroughly than an unauthenticated scan.
Why the other options are wrong
- A. An external scan refers to the origin of the scan (from outside the network), not the level of access.
- B. A gray-box scan has some limited knowledge or partial credentials, but not full admin access.
- C. A black-box scan has no prior internal knowledge or credentials.
White-box Scan
A vulnerability scan performed with full knowledge of the target system's internal structure, configuration, and often, administrator-level credentials.
- Provides the most comprehensive view of vulnerabilities.
- Requires credentials for deeper inspection.
- Identifies misconfigurations and patch deficiencies.
Memory trick: Box colors show how much you know.